TL;DR
Google shipped a Chrome security update for the stable desktop channel. It fixes 41 vulnerabilities in total. Six of them carry a critical rating. Users should update to version 151.0.7922.108 as soon as possible.
- Total: 6 CVEs
- Severity: 2 Critical · 3 High · 1 Unrated
- Actively exploited: None confirmed
- Highest severity: 9.6 (Critical · CVSSv3) — CVE-2026-19149
- Action: Apply the latest security updates now
Notable CVEs
| CVE | CVSS (CVSSv3) | Type | Fixed in | Status |
|---|---|---|---|---|
| CVE-2026-19149 | 9.6 | CWE-416 | 151.0.7922.109 | Not exploited |
| CVE-2026-19170 | 9.6 | CWE-416 | 151.0.7922.109 | Not exploited |
| CVE-2026-19137 | 8.3 | CWE-416 | 151.0.7922.109 | Not exploited |
| CVE-2026-19154 | 8.3 | CWE-416 | 151.0.7922.109 | Not exploited |
| CVE-2026-19172 | 8.3 | CWE-416 | 151.0.7922.109 | Not exploited |
| CVE-2026-19157 | Awaiting analysis | CWE-787 | 151.0.7922.109 | Not exploited |
Why it matters
Chrome runs on billions of devices worldwide. A memory-safety flaw can lead to a browser takeover. Therefore this Chrome security update matters for almost every desktop user.
What the flaws are
Most of the fixes address memory-safety bugs. Use-after-free issues dominate the list. The six critical flaws affect core components.
The critical bugs
Two critical flaws sit in WebGL, tracked as CVE-2026-19137 and CVE-2026-19170. Others affect Aura (CVE-2026-19149), Skia (CVE-2026-19154), ANGLE (CVE-2026-19157), and Views (CVE-2026-19172). Each could let a crafted web page corrupt memory in the browser.
External researchers credited
Google credited outside researchers for several fixes. One WebGL flaw came from a STAR Labs team. Google paid rewards of up to 5,000 dollars for some high-severity reports.
Exploitation status
Google has not reported any in-the-wild exploitation for these flaws. No public proof-of-concept has been confirmed. As usual, Google is keeping bug details restricted until most users update.
Affected versions
The flaws affect Chrome versions before the fixed build. This applies to Windows, Mac, and Linux.
Patch and mitigation
Update now. Google fixed the issues in Chrome 151.0.7922.108 and .109 for Windows and Mac, and 151.0.7922.108 for Linux. The rollout continues over the coming days and weeks. See the official Chrome stable channel update for the full list.
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.